Getting Data In

SC4S not able to parse syslog and ingest

wayne333
Engager

I've set up my SC4S and connected to my indexer. Logs are ingested as show below but further down, those does not get ingested, I see them while im listening with tcpdump. What have I missed?

Ingested

<174>2025-08-27T10:46:46.743660+08:00 idrac-xxxxxxxxxx1 Severity: Informational, Category: Audit, MessageID: USR0031, Message: Unable to log in for root from xxx.xxx.xx.32 using GUI

 

Not ingested

<190>Aug 27 09:59:52 xxxxxxxxO-DSSW6605 raslogd: AUDIT, 2025/08/27-09:59:52 (+08), [SNMP-3020], INFO, SECURITY, NONE/admin/xxx.xxx.xx.153/snmp/snmp,NA/xxxxxxxxO-DSSW6605/FID 128, 9.2.2, , , , , , , Event: Login, Info: SNMP login attempt via IP: xxx.xxx.xx.153, Last accessed user: , Success count: 0, Failure count: 1292, Time: Wed Aug 27 09:59:48 2025

<174>Aug 27 11:12:01 xxxxxxxxo-xxxxx1 hsm[4519]: info : 0 : Command: sysconf time 11:13 20250827 : admin : xxx.xxx.xx.32/57827
11:13:00.706364 veth0 Out IP xxx.xxx.xx.170.57454 > 1x.xx.x.8.514: SYSLOG local5.info, length: 125

 

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @wayne333 
Are you able to confirm that these events haven’t been indexed into a fallback index incase they weren’t properly typed by SC4S?

 

 

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma

wayne333
Engager

Hi @livehybrid,
Thanks for your time.


Yes , have checked the other default SC4S indexes as well. These 2 products with the same format of logs. The logs provided are from Brocade and Thales which are also known vendors in SC4S. 

Did I miss anything other than listening to the port in the env file?

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...